Report by Zero Networks

2026 Lateral Movement Exposure Report

7 FINDINGSPublished Jun 10, 2026
View Original Report →

Key Findings

East–West internal traffic represents more than 70% of a company’s communications and remains unprotected.

Network TrafficNetwork SecurityInternal Communications

78% of enterprise servers are reachable over SMB or WinRM, administrative protocols commonly exploited for ransomware spread and lateral movement.

SMBWinRMRansomwareEnterprise Servers

87% of enterprise servers accept inbound RDP or SSH connections from broad internal sources, giving attackers wide access pathways once inside the network.

Remote AccessNetwork SecurityRDPSSH

12% of organizations maintain direct user-to-server administrative pathways, meaning a single compromised employee device can provide immediate access to high-value systems.

Access ControlInsider RiskPrivileged Access

Roughly 80% of enterprises have deployed internal AI agents while two-thirds lack governance policies for those agents.

AI AgentsAI Governance

80% of enterprise servers are reachable from anywhere inside the network, creating greenfield conditions for ransomware, operational disruption, and full-environment compromise.

Network SecurityRansomwareLateral Movement

43% of internal authentication traffic still relies on NTLM, a legacy protocol frequently abused for credential replay and privilege escalation attacks.

Internal Authentication TrafficNTLMCredential Theft